Back to skill

Security audit

Uncle Matt's Build Me Something Anything

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local project generator with broad but disclosed workspace scanning and optional review tools, so users should set clear scan boundaries before running it.

Install only if you are comfortable with a skill that may inspect project/workspace evidence to infer creative patterns. Give concrete off-limits paths, avoid `nothing off-limits` on machines with client or private work, and approve AutoReview, ClawPatch, or missing-tool installs only if you trust the named external tools and the current package sources.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/review-closeout.md:7
Finding

Unpinned Third-Party Review Tools May Execute Mutable External Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:57-61, 101, 105; references/review-closeout.md:7-9, 34-52
Vulnerability Type: Supply-chain exposure through unpinned third-party tools
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:57-61:

text
AutoReview is the OpenClaw agent-skills structured code review helper from https://github.com/openclaw/agent-skills/tree/main/skills/autoreview, credited to OpenClaw agent-skills.
ClawPatch is the npm `clawpatch` automated code review/fix CLI from https://www.npmjs.com/package/clawpatch. npm metadata has listed maintainer `steipete`; refresh package metadata before installing and treat the refreshed metadata as current truth.

SKILL.md:101-105:

text
8. For substantial or unattended builds, read `references/unattended-orchestration.md` and use `$subagent-orchestrator` or available multi-agent tooling when present. Child agents should use the existing project folder and `context.md`.
9. Build the smallest complete version with a real first interaction.
10. If visual assets, sprites, icons, generated art, or audio matter, copy `assets/art-asset-plan-template.md` into the project as `assets/asset-plan.md` and use it.
11. Verify with the strongest local proof available: run/build/test, browser check, playtest, visual inspection, CLI sample, or whatever fits the artifact.
12. If AutoReview or ClawPatch were opted in, read `references/review-closeout.md`, run the chosen review/fix loop after normal proof, then rerun proof.

references/review-closeout.md:7-9:

text
- AutoReview: structured code review helper from OpenClaw agent-skills, https://github.com/openclaw/agent-skills/tree/main/skills/autoreview, credited to OpenClaw agent-skills.
- ClawPatch: npm `clawpatch` automated code review/fix CLI, https://www.npmjs.com/package/clawpatch. npm metadata has listed maintainer `steipete`; refresh npm metadata before install and use the refresh
...[truncated 3226 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin npm tools to an exact audited version rather than resolving the latest release.
  2. Pin GitHub-hosted helpers to an immutable commit SHA instead of a mutable branch or directory URL.
  3. Record and verify package integrity hashes and registry provenance before installation.
  4. Review downloaded package contents and installation scripts before first execution.
  5. Disable npm lifecycle scripts where the tool can operate without them.
  6. Run third-party review tools in an operating-system sandbox or container with:
    • only the generated project mounted writable;
    • unrelated local paths unavailable;
    • secrets and sensitive environment variables removed;
    • network access disabled unless demonstrably required;
    • strict process, time, and resource limits.
  7. Prefer review-only operation. Apply proposed changes through the main agent after independently inspecting each finding and patch.
  8. Document approved versions and require a new security review before updating them.

other

Note
Location
SKILL.md:70
Finding

Broad Workspace Discovery Can Read and Persist Unrelated Project Information

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:70-75, 96-98
Vulnerability Type: Excessive local data discovery
Risk Level: Low

Vulnerable Code Snippets

SKILL.md:70-75:

text
If the exact skill invocation explicitly requests unattended mode but gives no setup answer, scan the current repo/folder plus obvious sibling project/workspace roots. Connected drives/HDDs, installs, publishing, deployment, commits, pushes, paid actions, raw credential inspection, and destructive cleanup each need explicit permission.

When off-limits is `nothing off-limits`, start broad: current repo/folder, obvious sibling repos/workspaces, mounted project/workspace roots, manifests, README/docs, source filenames, route/component names, scripts, tests, and assets. Open project evidence first. Get specific approval before opening personal media, backups, client folders, browser data, mail, chat logs, financial records, secret files, or random private material.

SKILL.md:96-98:

text
4. Scan everything allowed after applying off-limits boundaries. Prefer names, paths, manifests, README/docs, source filenames, route/component names, scripts, tests, and assets before opening lots of content.
5. In `context.md`, record the evidence, the user's repeated lanes, the rut diagnosis, rejected obvious ideas, and the chosen idea.
6. Choose one idea yourself. Ground it in the scan evidence.

Technical Analysis

The Skill interprets broad shorthand consent, including nothing off-limits, as authorization to scan not only the active repository but also “obvious” sibling and mounted workspace roots. Those roots are not required to be enumerated and confirmed before access. The discovery process can inspect filenames, manifests, documentation, tests, scripts, assets, routes, and component names.

Such metadata can reveal proprietary project names, client identities, product plans, technology choices, internal routes, and unfin ...[truncated 2021 chars]

Remediation
View remediation

Remediation Suggestions

  1. Restrict default discovery to the current repository or explicitly supplied root.
  2. Resolve all candidate paths first, display their canonical paths, and require explicit per-root approval before reading them.
  3. Do not treat nothing off-limits as implicit authorization for unknown mounted or sibling workspaces.
  4. Apply configurable limits for directory depth, file count, file size, and discovery duration.
  5. Separate metadata discovery from content access and request additional consent before opening documentation, source files, tests, or assets outside the active repository.
  6. Exclude client workspaces, mounted drives, backups, hidden directories, and repositories with restrictive markers by default.
  7. Store only the minimum evidence required in context.md; prefer generalized conclusions over filenames, paths, or copied text.
  8. Sanitize client names, account handles, personal identifiers, and absolute paths before persistence.
  9. Add a final privacy review that lists the source roots used and removes evidence unrelated to the generated project.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames the skill as scanning only allowed project/workspace evidence, but the body expands scope to sibling repos, mounted roots, and even private categories once the agent seeks approval. That mismatch can mislead users and downstream policy systems about the true data-access surface, increasing the chance of over-collection of sensitive local information during execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill allows optional installation of tools and package metadata refreshes as part of setup, even though its primary role is generating a local project. Introducing install behavior expands the attack surface to supply-chain risk, unexpected system modification, and network access that users may not anticipate from a project-creation skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest describes a single local project generator workflow, but the file directs the agent to invoke subagent orchestration or multi-agent tooling for substantial or unattended builds. Delegating work to additional agents is a distinct operational capability that is not apparent from the stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.